83% ip-vault-wp-firewall

Code Review | Two-factor authentication (formerly IP Vault)

WordPress plugin Two-factor authentication (formerly IP Vault) scored83%from 54 tests.

About plugin

  • Plugin page: ip-vault-wp-firewall
  • Plugin version: 2.1
  • PHP compatiblity: 7.0+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.0-6.2.2
  • WordPress version: 6.3.1
  • First release: Dec 1, 2020
  • Latest release: Jun 6, 2023
  • Number of updates: 20
  • Update frequency: every 45.9 days
  • Top authors: youtag (100%)

Code review

54 tests

User reviews

1 review

Install metrics

20+ active /683 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
This plugin's installer ran successfully

Server metrics [RAM: ▲0.09MB] [CPU: ▼4.70ms] Passed 4 tests

Analyzing server-side resources used by Two-factor authentication (formerly IP Vault)
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /3.56 ▲0.1042.66 ▼0.50
Dashboard /wp-admin3.40 ▲0.0953.59 ▼5.47
Posts /wp-admin/edit.php3.51 ▲0.1547.69 ▼2.04
Add New Post /wp-admin/post-new.php5.97 ▲0.0886.34 ▼10.80
Media Library /wp-admin/upload.php3.32 ▲0.0843.02 ▲7.32

Server storage [IO: ▲1.85MB] [DB: ▲0.00MB] Passed 3 tests

How much does this plugin use your filesystem and database?
There were no storage issued detected upon installing this plugin
Filesystem: 23 new files
Database: 1 new table, 16 new options
New tables
wp_ipv_logs
New WordPress options
ipv_use_asn
widget_recent-comments
ipv_home_path
db_upgraded
can_compress_scripts
ipv_request_excludes
ipv_modus
widget_recent-posts
ipv_whitelist
ipv_gdpr_ips
...

Browser metrics Passed 4 tests

Checking browser requirements for Two-factor authentication (formerly IP Vault)
This plugin renders optimally with no browser resource issues detected
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,846 ▲6014.48 ▲0.221.78 ▼0.1943.54 ▼0.12
Dashboard /wp-admin2,243 ▲725.61 ▼0.0395.01 ▼5.4442.78 ▼1.12
Posts /wp-admin/edit.php2,112 ▲121.97 ▼0.0034.90 ▼2.6033.64 ▼1.60
Add New Post /wp-admin/post-new.php1,536 ▼123.14 ▼0.00669.62 ▼11.1853.96 ▲1.23
Media Library /wp-admin/upload.php1,412 ▲154.19 ▼0.0495.28 ▼10.0244.47 ▼1.91

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
You still need to fix the following
  • Zombie WordPress options were found after uninstall: 6 options
    • widget_theysaidso_widget
    • widget_recent-posts
    • theysaidso_admin_options
    • db_upgraded
    • widget_recent-comments
    • can_compress_scripts

Smoke tests 75% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for server-side errors
The smoke test was a success, however most plugin functionality was not tested

SRP 50% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Almost there! Just fix the following items
  • 3× GET requests to PHP files return non-empty strings:
    • > /wp-content/plugins/ip-vault-wp-firewall/uninstall.php
    • > /wp-content/plugins/ip-vault-wp-firewall/includes/admin-chart.php
    • > /wp-content/plugins/ip-vault-wp-firewall/ip-vault.php

User-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
No browser issues were found

Optimizations

Plugin configuration 90% from 29 tests

readme.txt Passed 16 tests

The readme.txt file is an important file in your plugin as it is parsed by WordPress.org to prepare the public listing of your plugin
5 plugin tags: brute force, protection, security, ip, lock

ip-vault-wp-firewall/ip-vault.php 77% from 13 tests

This is the main PHP file of "Two-factor authentication (formerly IP Vault)" version 2.1, providing information about the plugin in the header fields and serving as the principal entry point to the plugin's functions
Please make the necessary changes and fix the following:
  • Main file name: Even though not officially enforced, the main plugin file should be the same as the plugin slug ("ip-vault-wp-firewall.php" instead of "ip-vault.php")
  • Description: The description should be shorter than 140 characters (currently 162 characters long)
  • Text Domain: The text domain is optional since WordPress version 4.6; if you do specify it, it must be the same as the plugin slug

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of file extensions present in this plugin and a short test that no dangerous files are bundled with this plugin
Good job! No executable or dangerous file extensions detected2,001 lines of code in 15 files:
LanguageFilesBlank linesComment linesLines of code
PHP105201391,140
SVG3128524
CSS219337

PHP code Passed 2 tests

A short review of cyclomatic complexity and code structure
There were no cyclomatic complexity issued detected
Cyclomatic complexity
Average complexity per logical line of code0.36
Average class complexity48.00
▷ Minimum class complexity48.00
▷ Maximum class complexity48.00
Average method complexity2.68
▷ Minimum method complexity1.00
▷ Maximum method complexity7.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes1
▷ Abstract classes00.00%
▷ Concrete classes1100.00%
▷ Final classes00.00%
Methods28
▷ Static methods00.00%
▷ Public methods28100.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions10
▷ Named functions10100.00%
▷ Anonymous functions00.00%
Constants4
▷ Global constants4100.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size 50% from 2 tests

Image compression 50% from 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
5 PNG files occupy 1.49MB with 0.79MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/screenshot-4.png222.88KB97.82KB▼ 56.11%
assets/screenshot-3.png172.55KB95.86KB▼ 44.45%
assets/screenshot-1.png673.54KB309.38KB▼ 54.07%
assets/screenshot-5.png272.19KB104.10KB▼ 61.75%
assets/screenshot-2.png183.09KB95.41KB▼ 47.89%